Summary
In short
- The log exists to produce a roll call. A record of arrivals without reliable departures cannot do that, and it will send people back into a building during an evacuation.
- Host accountability is the most effective control and requires no technology: each visitor is the named responsibility of an employee who accounts for them at the assembly point.
- Under the FSMA Intentional Adulteration rule, access control can be a mitigation strategy at actionable process steps, which makes the log part of the food defense plan rather than a reception formality.
- Visitor records are personal data with a retention period, and most logs are kept indefinitely because nobody set one.
- A paper book at an unstaffed reception is not a control outside working hours, which is when contractor-heavy and out-of-hours activity occurs.
- The test is a drill on a day with visitors present, timing how long it takes to reach a definitive answer about every one of them.
What it is
What it is
What is a visitor log?
The record of who is on site who is not an employee or an inducted contractor, capturing arrival, departure, host and purpose, and supporting emergency accountability and site security.
Why does departure matter more than arrival?
Because arrival is easy to capture and tells you nothing during an emergency. A log that records arrivals produces a list of people who may or may not still be present, and acting on it means searching a building for people who have gone home.
When to use it
When to use it, and when not to
This records presence. The induction and the access decision sit separately.
Use it for
- Recording arrival and departure of visitors, including delivery drivers entering beyond a defined boundary
- Supporting emergency roll call and accountability
- Evidencing access control where it forms part of a food defense mitigation strategy
- Establishing who was on site at a given time, for security or investigation purposes
- Identifying the host responsible for each visitor
Not for
- Visitor induction, which delivers the safety briefing
- Site access authorisation, determining which areas a person may enter
- Contractor management, which covers people performing work rather than visiting
- The food defense plan, which this record supports at specific process steps
- Security incident reporting, which records events rather than presence
Standards
What it is built against
Visitor records sit across emergency planning, food defense and privacy obligations.
| Clause | Requirement | Where it lands |
|---|---|---|
| 29 CFR 1910.38(c)(4) | Procedures to account for all employees and others after evacuation is complete | Day summary |
| 21 CFR Part 121 | Access control as a mitigation strategy where visitor access reaches actionable process steps | Related records |
| ISO 45001 cl.8.2 | Emergency preparedness and response covering everyone on the premises | Day summary |
| ISO 45001 cl.7.3 | Awareness for persons under the organisation's control, including visitors | Visitors |
| ISO 27001 A.7 | Physical entry controls including visitor registration and supervision | Visitors |
| GFSI schemes | Site security and visitor control including access to production areas | Related records |
| GDPR / privacy law | Visitor records are personal data requiring a defined retention period and lawful basis | Header |
| RRFSO art.9 (GB) | Fire risk assessment covering relevant persons, which includes visitors | Day summary |
What it does not cover
- Visitor induction, delivering the safety briefing on arrival.
- Site access authorisation, determining which areas may be entered.
- Contractor management, covering people performing work.
- The food defense plan, which this record supports at specific steps.
- Security incident reporting, recording events rather than presence.
Filling it in
Filling it in well
Capture both directions, name a host, and test it during a drill.
Either record leaving as reliably as arriving, through access control at both directions, or remove the dependency by assigning host accountability. A sign-out column relies on people choosing to stop at a desk they have no reason to stop at, and it fails silently every day.
A specific employee, recorded by name, who knows where their visitor is and accounts for them at the assembly point. This is the single most effective element of visitor management, it costs nothing, and it converts an unanswerable question into a person who knows the answer.
Where visitor access reaches an actionable process step, access control may be a mitigation strategy under the Intentional Adulteration rule. That makes the log part of a regulated plan with monitoring and verification requirements, rather than a reception courtesy.
Visitor logs are personal data. Most are retained indefinitely because nobody decided otherwise, which creates an obligation nobody is managing. Setting a period appropriate to the purpose, and applying it, is straightforward and routinely absent.
Audit findings
Common audit findings
Visitor log findings concentrate on departures and on what the log is for.
| Finding | Clause | What fixes it |
|---|---|---|
| Departures not reliably captured, so no roll call is possible. | 1910.38(c)(4) | Capture both directions or assign host accountability. |
| No named host, so nobody knows where a visitor is. | ISO 45001 cl.8.2 | Assign by name; it is the most effective control and costs nothing. |
| Paper book at an unstaffed reception outside working hours. | 1910.38(c)(4) | Out of hours is when contractor-heavy activity occurs and reception is closed. |
| Visitors entering production areas unescorted. | 21 CFR Part 121 | Escort in restricted areas; unaccompanied access defeats hygiene and defense controls. |
| Log not used during drills, so the gap is never found. | ISO 45001 cl.8.2 | Run a drill with visitors present and time the answer. |
| Delivery drivers entering beyond the yard without being logged. | ISO 45001 cl.7.3 | Set the boundary explicitly; the ambiguous middle is where people end up unlogged. |
| No retention period set for personal data. | GDPR | Visitor records are personal data; indefinite retention is an unmanaged obligation. |
| Access control not identified as a mitigation strategy where it functions as one. | 21 CFR Part 121 | Where it protects an actionable process step it carries monitoring and verification requirements. |
| Contractors logged as visitors rather than inducted. | ISO 45001 cl.8.1.4 | People performing work need full induction; distinguish at arrival. |
| Log not accessible at the assembly point during an evacuation. | 1910.38(c)(4) | A record inside the building being evacuated is not available when needed. |
Worked case
Case in point: the answer that took twenty minutes
A site ran an evacuation drill on a day with visitors present, deliberately, having never done so before. Employees assembled and were accounted for in under five minutes using the departmental roll call.
The visitor book listed nine names. Six people were at the assembly point. Establishing what had happened to the other three took just over twenty minutes: one had left after a morning meeting, one was with a host who had taken them out to a different building, and one had signed in with a company name and an illegible signature and could not be identified at all.
In a real evacuation the site would have had three unaccounted names, one of them unidentifiable, and a fire officer asking whether the building was clear.
Definitions
Definitions and key terms
- Roll call
- Accounting for everyone after evacuation, requiring knowledge of who is currently present rather than who arrived.
- Host accountability
- An arrangement making a named employee responsible for their visitor, including at the assembly point.
- Actionable process step
- Under the Intentional Adulteration rule, a point where a significant vulnerability exists and mitigation applies.
- Mitigation strategy
- A measure applied at an actionable process step, with monitoring and verification requirements attached.
- Escorted access
- Requiring accompaniment in defined areas, effective only where the escort remains present.
- Boundary definition
- The point beyond which someone must be logged and inducted, which needs stating explicitly.
- Retention period
- How long visitor records are kept, required because they constitute personal data.
- Assembly point availability
- Whether the record can be read during an evacuation, which a system inside the building cannot.
FAQ
Frequently asked questions
What is the visitor log actually for?+
Answering who is inside the building right now, during an evacuation. Everything else it does is secondary. A log recording arrivals produces a list of people who may or may not still be present, and acting on it means sending marshals back into a building to look for people who left hours earlier.
Why does sign-out fail?+
Because leaving is unstructured. Arrival has a natural pause at a desk; departure does not. People leave with their host through another door, leave when a meeting overruns, or walk to a car park past a desk they have no reason to approach. The column exists and is not used, which is worse than not having it because it looks like a control.
What is the simplest fix?+
Host accountability. Each visitor is the named responsibility of an employee who knows where they are and accounts for them at the assembly point. It requires no technology, works during a power failure, survives an evacuation of the building containing the system, and produces a person who knows the answer rather than a list that might.
Does the log form part of food defense?+
It can. Under the Intentional Adulteration rule, access control may be a mitigation strategy where visitor access reaches an actionable process step, which brings monitoring, corrective action and verification requirements. Where that applies, the log is part of a regulated plan rather than a reception formality.
How do we know whether ours works?+
Run a drill on a day when visitors are on site and time how long it takes to reach a definitive answer about every one of them. Most sites have never done this, because drills are scheduled on convenient days and visitors are not part of the count. It is one afternoon and it tests the element most likely to fail.
The agents
What the agents do with it
The log answers who is present. What fails is the departure nobody captured and the drill that never included visitors.
Captures arrival and departure with a named host, and makes the current presence list available at the assembly point rather than inside the building.
Distinguishes visitors from people performing work at arrival, routing the second to full induction.
Connects visitor access control to the food defense plan where it protects an actionable process step.
Includes visitors in drill accountability and records how long a definitive answer took, which is the measure that matters.
This template lives in KnowOps — frontline execution. Shift handover, production control, daily management, worker lifecycle and improvement.
Sources
Sources
- 29 CFR 1910.38, emergency action plans, including accounting for employees, OSHA
- 21 CFR Part 121, mitigation strategies to protect food against intentional adulteration, FDA
- ISO 45001:2018 clauses 7.3 and 8.2
- ISO/IEC 27001 Annex A.7, physical and environmental security
- BRCGS Food Safety Issue 9 and SQF Edition 9, site security and visitor control